Case study: How predictive shielding in Defender stopped GPO-based ransomware before it started
ID: 6dad82ea-2155-5256-86f3-87a7bd2f541a
STIX ID: report--6dad82ea-2155-5256-86f3-87a7bd2f541a
Feed Name: Microsoft Security
Date Published: 2026-03-23
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
Microsoft Defender disrupted a sophisticated, human-operated ransomware campaign targeting a large educational institution where attackers abused Group Policy Objects to disable protections and deploy ransomware via scheduled tasks and SMB; Defender's predictive shielding and attack disruption prevented GPO-based encryption across ~700 devices, blocked roughly 97% of attempted encryption, and contained remaining impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
